Zscaler, Inc. (ZS) Earnings Call Transcript & Summary

September 24, 2020

NASDAQ US Information Technology Software special 53 min

Earnings Call Speaker Segments

Mandeep Singh

analyst
#1

Good morning, everyone. I appreciate you joining us today for this call with Zscaler. I'm Mandeep Singh, senior analyst at Bloomberg Intelligence covering the cybersecurity and the infrastructure software space. The format of this session will be Q&A. This -- a couple of housekeeping items. Today's presentation will be recorded and available for playback. There is a chat box where you, the audience can ask questions. The questions are anonymous. So we are not going to mention your company name or affiliation. And with that, let's kick it off. So we have Jay Chaudhry, CEO of Zscaler with us. Zscaler, as the audience will know, is a pioneer in cloud-based network security and has been a leader in using this new architecture called SASE, which is a Gartner term. And thank you so much, Jay, for joining us today. I think it would be most useful to dedicate this time to the qualitative elements in our discussion. And before I start with questions, do you want to maybe kick us off with some high-level comments around how the compute and storage have seen a much faster shift to cloud with the infrastructure as a service offerings from hyperscale cloud vendors, but on the networking side and I guess security goes hand in hand with networking, it's been still compared to the computer and storage. So maybe if you can start off there and then we'll get into the questions.

Jagtar Chaudhry

executive
#2

Sure. Mandeep, thank you for the opportunity. Many times, people question about cloud shouldn't happen, should network move, should security move. To me, everything stocks as a cottage industry, then they move to professionally managed services. That's what happened to electricity, compute moving to the cloud is a natural thing, network and security has to happen. It just has taken longer because for compute, you can lift and shift and move it over. Network needed a little bit more work. But with the advent of Internet everywhere with fast mobile connectivity with 4G and 5G, it's happening at a faster pace, the pace we've never seen before, and COVID actually has accelerated it. It should be an interesting comment. I was talking to a CIO who actually wants to deploy Zscaler, and the networking team was taking time figuring out how do you do it because it's a massive network. And the CIO -- this new CIO, who come to this company called me, he said, "I got 100,000 employees, and they need to work from home." And I said, "Great. How is the networking side looking like?" He said, "I don't need to talk to my networking team. My people go direct from home over broadband or 4G through your service. They'll access whatever they need to access. Network, it doesn't really matter to me." So this was actually a big mind-shift change that COVID has caused. We all knew that Internet is becoming the new network. But there was some inertia holding back and COVID has kicked it off. We believe that this COVID is not a onetime thing. It's changing that any traffic of any employee can go over the Internet through a security, zero trust exchange like Zscaler, so it's fundamentally disrupting traditional network and traditional security, and it's accelerating.

Mandeep Singh

analyst
#3

Great. Thank you for the intro. So maybe let's get into the proxy aspect of your architecture. So proxy market was never that big. And when we look at IDC and Gartner estimates, they think the CASB, the software, gateway, is about a $2 billion market. And if you compare that to network security and appliances, that's about $15 billion to $20 billion market. So why do you think proxy architecture has potential in terms of capping this greenfield opportunity around going from hardware appliances to a more proxy based architecture? And if you tie that in with the SASE approach, that will be great.

Jagtar Chaudhry

executive
#4

Yes. Yes. Very good question. I think it's worthwhile because it sounds confusing, especially the vendors who are getting disrupted in the legacy market, they want to make it more confusing. Let's look at what was the role of security. There was 2 big roles, protect your servers and your campus and data center with firewall, they're like door, the gate in front, who can come in. So that's what firewalls traditionally did. Proxy was put in place for any user traffic that employees who needed to go to the Internet. They went through proxy and proxy was better for inspecting traffic. It's like a check post that can open up things and say, is any good stuff leaking out? Is any bad stuff coming in infecting you? So since in old -- over the past years, the number of users who went to the Internet traditionally was small. So the market for outbound user traffic was small. And outbound user traffic inspection was done by proxy, by most enterprises, except some of the low-end companies who didn't own understand security, they probably use some UTMs and firewalls and alike. Now look at today's world, every employee is working from wherever. So every employee needs to go through some kind of security check post, and that's where proxy comes in. That's why the market for inspecting, for securely connecting users to applications. When no one is on the network is becoming -- it's growing at a much faster pace. In fact, they used to be a notion, that I'm on my corporate network. That's my trusted network. I am in the castle, I'm secure. If I'm outside my company, I'm remote. I'm not on a trusted network. I need to come back to trust a network and go out. That was a silly world. That was the world of castle-and-moat security. That's the world that firewalls and appliances enabled. In today's world, you cannot do network security. Now that's a strong statement. You would say, wow, $20 billion, whatever billion market. And are you saying that it means nothing? This is how you should think about it. What does the term network security mean? It means securing your network. You could do it when you control the network. You have your private MPLS network between your branches and data centers and alike. Today, Internet is your network. We're going from owner broadband, you're going on a 4G connection. Tomorrow, you'll be on a 5G connection so fast that you'll never connect to a Wi-Fi in the office. So how you don't control the network, you don't secure the network. So you basically don't need to do traditional network security, that firewalls or the walls do. You securely need to connect users to application on any network. I'm not saying network is not important. Network is an important transport, but it's not something you're controlling. So think of the Zscaler approach. We said we are a zero trust exchange, a sophisticated exchange maybe in layman's terminology, it's an intelligent switch board. A user comes to us and says, "I need to talk to this person. I need to connect to this application." We validate, we verify, who are you? Are you supposed to connect this application or not? If the policy says, yes, we connect. If the policy says, no, we don't. It doesn't matter if the user is at home or a coffee shop or airport. That's why Zscaler was designed for this world and legacy appliances were not. So it's a matter of time, you will see the network security market going down and the zero trust approach where you don't secure the network will grow rapidly. And that's what I'm seeing a lot of the companies doing. We got just shy of 25% of Global 2,000 companies who actually -- all of their traffic goes through Zscaler and we act as a check post. So we think it's a matter of time that there won't be any firewalls out there. In the data center, they'll linger on for a while, but in the public cloud, there will be very hard for them to be able to deploy and manage.

Mandeep Singh

analyst
#5

That makes a lot of sense, Jay. So one question I get on a related note, since you mentioned MPLS and appliances, is performance. I guess with the Zscaler approach, how scalable it is? Is there a customer threshold where you have to add capacity in your data centers?

Jagtar Chaudhry

executive
#6

So first of all, there's a design goal of everything you build. When you build a power generator to sell to a home user, you look at the capacity of it, then you optimize for it. When you build a power plant to provide power to the entire city, you have a different design and different architecture. So appliances are built for the scale to handle a company, a large company, and they may get 20, 30, 50 appliances works. Zscaler was built as a big service. It's like DVD players versus Netflix. When you build Netflix streaming service, you know it can scale. So just to give you a little data point on scale, we handle about 130 billion requests per day that go through Zscaler. What's a request? When I go and send an e-mail out, it goes through us, it's one request. When I go and download, go to google.com, it's a request. Just to give you context of what 130 billion requests a day means. Google searches on a daily basis add up to about 8 billion to 9 billion. So we handle about 12 to 13x more traffic, more request than Google searches. So obviously, we can scale. By the way, the name Zscaler stands for Zenith of Scalability. When I started the company, I understood that appliances -- sorry, companies have to buy so many security appliances. And in fact, one CISO said, he got appliance fatigue, and the second one used the term appliance overload. And I wanted to make sure that we can scale, so we don't have to keep on buying so many boxes because at the end of the day, your software has to run on hardware. But when you design, when you do a cloud-native service like Zscaler, we are actually designed to be highly scalable because of the architecture. So many times when I've gone into large customers, I had one customer in Europe. These guys had 2 racks of traditional proxy appliances, I won't name the vendor on the call, but it's a high-end proxy vendor, 2 racks. And they basically pointed the traffic to us. At that time, we kind of were able to handle it in about 2 sets of 2 Intel servers. 4 servers was 8 racks. It's because you're designed to scale. And that's why during COVID time, when our ZPA traffic went 10x, that's not 10%, 10x is 1,000%. Within a few weeks, we were able to scale and handle it. So typically, a cloud-native service scales and can handle well. Appliance-based service doesn't scale, and you try to throw on more and more boxes of VMs, but it's such a cloudy solution. That's why I'd like to say, you can build the Netflix with DVD players.

Mandeep Singh

analyst
#7

Got it. That makes a lot of sense. So I guess, let's move to the public cloud vendors. I want to get a sense from you, why you think the public cloud security that's coming from Amazon or Azure or Google, why is that not enough? And the other question that I get from investors is when you look at other cloud security vendors like Okta and CrowdStrike, they are deploying on AWS on the public cloud. So why is Zscaler, I guess, building its own data center footprint? So if you can touch on those, that will be great.

Jagtar Chaudhry

executive
#8

Yes. So you've got 2 pretty meaningful questions actually. The first is a competitive question, cloud vendors. So security can get very complicated. And vendors don't help because they all try to use the same terms. But think of security in a very simple model, either you're protecting the user, so user doesn't infect it and infect everything else; or you're protecting data and servers because if bad guys get to your and data and applications, they can steal stuff away. That's a simplistic model, okay? The Zscaler is user-centric. For example, when we -- all traffic off, say, GE, every employee in every part of the world, when they connect to the Internet, they get redirected to Zscaler. So and these ask, where are you trying to go to, should you go there, should you not go there? So for GE, they may be going to 1,000 destinations. They may be going to 100 SaaS applications, and they may go to Office 365, and they may go to 10 applications in Azure and 50 applications in AWS. So we are sitting in the path to protect all users. The cloud vendors are trying to make sure their applications that are running on the cloud are secure and access security. So their primary focus is not to figure out where GE's all traffic is going. Probably 60% of traffic is going somewhere else. It's not even to public cloud. So their #1 priority is their applications, rather than traffic going to Netflix or Facebook or some of the crazy sites. So they are more focused on servers. We are user centric. We are basically saying which user can go where. So strategically, they will build more and more things that are front-ending servers. They will load balance. They'll bring probably some DDOS protection and like that. But they don't -- they are not a secure web gateway. They're not a SASE by any means at all, so they are complementary to us, okay? Now if you look at -- so that's the first part. If you look at the second part of the question, why build -- why not build it on AWS kind of stuff? That's a very, very good question. So think of applications or vendors, the 2 types of vendors. Vendor number one, they are a destination, they offer applications. When I go to Salesforce, whether I'm sitting in Chicago or Paris or Mumbai, I go to the same destination data center servers that may be sitting in San Francisco or maybe Chicago. It doesn't matter. The further I come from, the lower that response time, but I have one place to go. So applications are destinations. So it is easy to put applications on public cloud because public cloud is essentially a destination. Now Zscaler is not a destination. We are sitting in path, in traffic line, and we must sit in 100-plus locations because we're a check post. Think of this way. Imagine if U.S. had only 2 international airport you could fly out of the country, then you'll be all flying to that international airport and then flying out, not a good idea. In the same way, the public cloud, the destination where you can spin firewalls or put stuff out there are relatively few. They are about 2 dozen globally. They have a lot of what I call collection points where traffic can be backhauled. Now for Okta, it's okay to have it in AWS because Okta does not sit in line. For example, let me put it this way. When I go for an international trip, they stop me at the airport, they check my passport. They scan the passport and the computer makes a call to a database or passport to see if Jay's passport is valid and is he allowed to go to this country. Okta is the directory service, is like the passport computer that's sitting in a central location. It doesn't need to sit at hundreds of locations. But the international check post, the TSA, the passport has to be in every international airport. So since we are so distributed, we are sitting in 150 data center where we enforce policy, the traffic will move faster. For example, if I fly from San Francisco to Chicago and go via Dallas, it's not good. Speed of light is speed of light. So hence, I need a bigger distribution of data centers, just like -- I mean I'll give you an example. It's opposite example, but it's meaningful. Why does Akamai has so many locations? Because their cashing content in every city. Their cashing content gets picked up by users from a local city. We end up being a local security check post to enforce policy, and public cloud vendors are not motivated to spread the data centers everywhere. They want it, but there's a lot of cost involved and whatnot. So for hosting firewalls and security gear, whether it's Google or Microsoft or AWS, it's sitting at about 2 dozen data centers. Now we can use them. We do use them where it makes sense. For example, when ZPA traffic grew, we were able to send some of the overflow of traffic there. So that's also -- the second reason is also gross margins. A vendor like Okta, which does not sit in the traffic path, it's only authentication. Doesn't take tons of traffic. So their gross margin will not be impacted. But if you're sitting in line, for example, a firewall vendor trying to, say, I become a cloud service, the gross margins will be impacted big time. If you want to read a case study that was done by Dropbox, they kind of said, "When we were on AWS, here was my cost. When I brought it back to my data center, my gross margins went up significantly." So 2 reasons: response time for users, very important; gross margins for a public company. Those are the 2 big reasons why you need to have distributed data centers that public clouds just don't offer.

Mandeep Singh

analyst
#9

Got it. That's very helpful, Jay. And just to piggyback on your comments. So does that mean Zscaler can get into CDN or DDOS security if they wanted to?

Jagtar Chaudhry

executive
#10

Yes. From a person's point of view, we have the infrastructure to be able to do that. But they are very picky about the market we want to get into and the market we don't want to get into. I mean, I have North Star from very early on. My North Star was, I want to make sure we become the zero trust exchange and switchboard. I have a core competency of figuring out, validating who you are and connecting the right application or service. So we started with ZIA, where I could connect users to external applications, then I literally doubled my market TAM by introducing ZPA, where users could connect to internal applications in your data center or in a public cloud. Then we added Zscaler's digital experience, ZDX, because when I'm setting the traffic path, there's nobody who can tell you better what's the user experience, response time end-to-end. So we entered that market. We recently started shipping the product a few months ago, a closing deal. And then the fourth market, which is in my bull's eye with concentric circles would be application-to-application communication because a lot of these workloads need to talk to securely, and we are the natural switchboard. So those are the areas I described, which are natural based on where I sit and the core competency I have. Now CDN is an interesting market. It's cashing, right? It's a mature market. I do believe that every big cloud provider wants to do CDN for the services they offer. And they will be bigger and bigger, dominant players. So we -- even though we have the distributed infrastructure to do CDN, that's not a good enough reason for us to get into the market. We look at strategic fit, we look at core competencies, and that's how we decide which market to go after, which market is not. The TAM of the market we're going after is large. It is growing significantly. I think the biggest market for us, even after ZIA, ZPA will be this public cloud inside the data center where you want to do application segmentation without having to do old-school legacy network segmentation. It's a nascent market right now, but as thousands and thousands of workloads get spun out there, old-school virtual firewalls won't work and a disruptive technology like Zscaler offers us an opportunity. So we're going after -- I like to go after newer market where I can disrupt something. I don't like to be a me too in a market where things have been done for years. And I don't like to say I can do better and cheaper. I want to say, I'm giving you a disruptive, far better technology, and the cloud and mobility is actually ideal shift to -- able to be able to do that.

Mandeep Singh

analyst
#11

Great. And that's a perfect segue into my next question. Since you mentioned Zscaler is focused on users, so do you think the lines are blurring between network and endpoint security? I mean, CrowdStrike, they announced an acquisition last night of this company to expand into SASE, and they have been talking a lot about workload security more and more. I just wanted to maybe spend some time on how do you think this market evolves? Because right now, there is a lot of fragmentation. Somebody is doing work with security, somebody is doing SIM. There are all these different vectors. Like as a vendor who is trying to tie everything together with SASE, which is, I think the focus of the approach is that you tie in CASB and gateway and whatever you can and should converge. So how do you see all these other vectors like TAM, like workload security, how do these fit into your core offering?

Jagtar Chaudhry

executive
#12

Yes. So we spend tons of time thinking about it, talking to customers, whatnot. Here's how you should think about. Today, there's so many point products. An average large customer may have 50, 100, 200 security point products. That's not practical to do. They're all sick and tired of it. On the other extreme, there's no such thing as one god security box or god security cloud that can do everything. But consolidation is happening, it's bound to happen, but it will happen along a meaningful platform. SASE is block framework, a loose collection of many pieces. In fact, Gartner interviewed a lot of comers to say how are you embracing the cloud. They found 2 common things from lots of those interviews: One, they're all using Zscaler of a cloud security because we have pioneered it; and they're all trying to deploy SD-WAN and that SD-WAN traffic came to us because we became the security provider. So that's how the SASE term got point. But if you look at the platform, it needs to be, so we -- Zscaler is a zero trust exchange platform for all stuff that should be done to inspect traffic to connect the right party to right party, it maybe users to applications, it may be application to applications. And all those things need to be brought together under one platform. For example, there's no point in having a stand-alone vendor to provide sandboxing. If you're sitting in traffic, you should do sandboxing. There's no need to get one more vendor to do DLP. Data protection should be done by the vendor like Zscaler, who's sitting in line. So that's the platform. To me, identity is a separate piece. It sits outside. That's why we think there are vendors like Microsoft, Azure Ad and Okta, who are identity provider will do -- are doing a great job. Endpoint is becoming a platform with 2 things: one is endpoint security; second, is endpoint management. They both need to come together, and they're coming together. Microsoft is doing it, VMWare is doing it. And when CrowdStrike runs on workloads, obviously, the same approach. If you're running something on endpoint to secure the endpoint to make sure it's not infected. You can put the same kind of technology on a workload, which is a server type of SaaS to do the testing. But it's not them. It's -- so security will then a couple of layers. Here is why I look at security 4 or so buckets. We are sitting in line like an international airport, inspecting, making sure we enforce policy. You can't enforce policy unless you're sitting in line. Identity will verify who the person is. Endpoint makes sure endpoint is not infected, and it has the right posture, security posture. And that's why CrowdStrike acquisition -- recent acquisition. And then you mentioned log consolidation to feed logs. So you're seeing essentially 4 -- the 5 SD-WAN being able to send traffic. The whole complicated stuff will boil down to 4 or 5 platforms, and we are one of those critical platforms. We think our TAM is growing rapidly along the areas where we are. I don't need to jump into other areas where the market is crowded, and you become a me too. For example, have you ever seen a network security vendor dominate endpoint? I haven't. Have you seen an endpoint vendor trying to dominate the network security proxy of the world? McAfee tried it, Symantec tried it for years, whatever happened, it's kind of gone. So focusing on disruptive technology in a core competency and doing it extremely well is what we like to do. But we do see consolidation along platforms, and we are one of the key platforms, and we've integrated all of the leading platforms.

Mandeep Singh

analyst
#13

Makes sense. Thank you for that comment. So maybe we'll take an audience question. There's a question that is a proxy slower than single-pass architecture like Palo Alto Networks? I'm sure if you want to comment on it.

Jagtar Chaudhry

executive
#14

Yes. I'll tell you. I don't need to talk about vendors, but all firewalls have essentially some of the same architecture. But here is what happens. Think of -- I'll give you a metaphor, okay. A firewall is sitting in line, inspecting traffic, but it is not supposed to stop that traffic for inspection because it needs to go. For example, if you have a security check post on a highway, that's supposed to make sure that cars with weapons and guns aren't going through or they're looking for something bad. A firewall is like a check post sitting on the side, it's looking at running cars, drive cars that are running to see if something looks bad. If it does, maybe they can shoot the tires and make them flat and stop them. But they don't, you can only do so much inspection. Yes, a firewall -- anything that has no inspection will be the fastest. Firewall doesn't slow any connection. If it catches something, it's great. If it doesn't catch, it doesn't clear because the traffic is gone. A proxy is different. A proxy is like the check post on a highway, where you actually stop the traffic and say, "Tell me, I want to open the car, the hood, the trunk, see if there's anything bad." And then if something is bad, it gets stopped right there, it's all good, it's let go. Now if you think about it logically, to do all that needs a lot of work, how do you do it at a light speed, fast speed, that's a hard thing to do. So doing a proxy is -- doing a proxy at light speed is very hard. One of the biggest core competency Zscaler has is to optimize a software to run it at a very fast speed with proper inspection. For example, firewalls can't do SSL inspection. Now they can bolt-on a proxy to do SSL inspection. I know some of these firewall guys who [indiscernible] proxy. And then you ask them, "Do you do SSL inspection?" They'll say, "Oh, yes, we do kind of, right?" How can you do it? The only way to do SSL inspection is to terminate a connection, look at the traffic and then resend it. That's called proxy. So it's a -- proxy done wrongly is slow. Proxy done right is fast. I do 130 billion transactions a day. My average proxy latency I had is not in millisecond, it's in microseconds. My customer boast about that user experience that [indiscernible] and we deliver. So we built the right proxy, right architecture that's fast and that also delivers a great, better security because of SSL inspection and better DLP. A firewall can't do proper data inspection at all. Why is that? Do a simple test. Take a PDF file with all the confidential documents in it. Send it through a firewall. It just passes through. It just can't inspect it. Now in a demo, they could try to send it to a proxy and cheat and they say, my firewall did it. Then they -- but they won't tell you that. I actually added a proxy on the back side to make it work. This is science. There's only one company that talks silly stuff and proxy is no good. If you talk to any smart guy out there, proxy if you control. If you talk to Akamai world, even on the server side, everyone has proxy for inspection, for traffic control and the like.

Mandeep Singh

analyst
#15

Got it. And again, just a reminder, if you have a question, there is a chat box where you can send your questions, then we'll be sure to get to them. We have about 10, 15 minutes remaining. I want to jump to platforms since you mentioned Zscaler will be one of the few platforms on the cloud security side. So is there an equivalent of an app store that you have? Or how do customers who about building like new functionality or building more connections or integrations? Does Zscaler have to do it? Or can the service -- the SIs do it? Just if you can elaborate on the platform aspect, it would be great.

Jagtar Chaudhry

executive
#16

Yes. So App Store comp step is needed when you have to download different apps, okay? And being able to deploy and use them. In this world of Zscaler as a switchboard, I do most of my integration right here from the switchboard, so customers doesn't need to do anything. For example, how do I integrate with Splunk to be able to send traffic to Splunk? You simply log on to Zscaler console, the customer does, and I give you options, say, you can send logs to these, these vendors that are already integrated. And you select the vendor, then you select some of the filters, integration is done. And your log starts showing up in Splunk, and there's already a pre-built application. Good example of it. For example, how do I integrate identity vendor, which may be Microsoft, Azure AD or Ping or OneLogin or SailPoint. You go to the console, you click, I let you say, you click, you single click, allow you to integrate with identity vendors. Microsoft Office 365, we've done integration. So you don't have to do it. Our goal is to do proper API-based integration. So it minimizes your deployment time, it actually makes it easy for you to operate it. And that's why everything about Zscaler is APIs. This application interfaces that are program interfaces. And that's why our customers love us. That's why when the customer said, I was able to roll out Zscaler in 2 weeks for 40,000 employees, 50,000 employees, the old world of appliance and all takes months and months for the same thing. So our platform and also take DLP, take sandboxing. If you have to do sandboxing, buy a stand-alone product like, say, FireEye. You go, you get, you deploy, you integrate, lots of steps needed. In the case of Zscaler, your traffic is going through Zscaler. You go to the console and say, I want to turn on a new feature called sandboxing. That's all you do. The traffic starts flowing through our sandbox service, we start opening zero-day files, figuring out what's good, what's bad and it's not enforcing it. So I have customers who have turned on sand boxing, in a matter of minutes, not even hours. That's the power of integrated platform.

Mandeep Singh

analyst
#17

Got it. And on the partner ecosystem, so you are the preferred vendor for Office 365 deployments. But you didn't joined the alliance with CrowdStrike, Okta, Proofpoint and Netscope. They recently announced this partnership. So is that because Zscaler has a different go-to-market strategy? Or they want to remain agnostic to, let's say, an Okta or an Azure Active Directory?

Jagtar Chaudhry

executive
#18

Yes. See, in this vendor world, the all kinds of alliances and partnerships. Some of these are serious integrations. Others are probably come together because they're worried about competitors and the like, okay? We, by and large, believe in doing real partnership with real and tight integration. For example, we are very tightly integrated with CrowdStrike, okay? I don't really need to announce this. I actually do lots of sales and marking together with CrowdStrike. They -- our field forces work together. It's a good thing. So that's Microsoft, same thing. Office 365 is in big demand from lots of customers. So by making sure it's tightly integrated, great response time, Microsoft Teams should work well. I have done integration of a tight partnership. Zoom is another thing where you can have slow performance because if you do, your quality of voice and video suffers. So we've done tight integration with Zoom. So we are integrated with all the vendors. We don't do a lot of press release, marketing partnerships. We do tight partnership with selected vendors, but we do integration with lots of vendors. And Microsoft is one of the peripheral partners. We do a lot of markets, you go-to-market, AWS as well in certain areas, pretty open to all the areas. But partnerships, some of these groups coming together, they're kind of probably trying to do it as a convenience to fend off some of the competition.

Mandeep Singh

analyst
#19

Got it. And just to build on that. So I guess from your perspective, what are the different signposts that we should look out for SASE acceptance given this is still a nascent market?

Jagtar Chaudhry

executive
#20

Right. SASE, I think if you ask me that the SASE is a broad framework, a collection of principles. The biggest thing that customers are doing today is zero trust networking. And SASE talks about zero trust architecture being a very important architecture. So there are 2 groundbreaking papers Gartner wrote in the past 2 years. SASE basically said your security must be enforced at the edge. And edge means it shouldn't be totally centralized, and it needs to come from these thin branches to distributed data centers like Zscaler. And then they said Zero Trust Network Access, ZTNA, the second white paper, second research note they published. Very impressive, where they basically said, putting users on the network is a dangerous thing. We should not connect user to the network, we should connect the user to a particular application or service. All network security vendors do the old architecture. It just -- and that architecture creates lots of security issues. One, machine gets infected on your network. And the entire network, basically X as a transport and every machine getting infected. So that's why the zero trust is becoming very important. So the way you will be able to see what is the acceptance of SASE, the best way to measure would be are they doing zero trust architecture or not because the SD-WAN vendor will have the definitive SASE because they've done SD-WAN. Somebody else will come from here. But overall, not putting users on the network by connecting them, doing the zero trust is the real measure. When I talk to CIOs, CISOs out there, about 7 out of 10 will tell me that they have a zero trust project. When Zscaler ZPA was bought during this time -- during the COVID time, it wasn't really bought to say, "I need to replace my VPN tomorrow, when my people are home, then I need to go away " They bought ZPA to get rid off this VPN as a Phase 1, but Phase 2 is I want zero trust or I don't put people on my network for security reasons. So measuring the acceptance of zero trust is probably the best way to measure the acceptance of SASE because it's -- the term SASE is a bit loose.

Mandeep Singh

analyst
#21

Got it. In fact, there is an audience question around this. Do you believe that ZPA product will replace traditional firewalls? And have you heard if customers are replacing firewalls with your existing products? You kind of answered that.

Jagtar Chaudhry

executive
#22

Yes, this question got asked quite often because firewall is such a big market, and investors are trying to figure out. So let me tell you how we look at it. In the world of zero trust, in the world of Zscaler, the applications are destinations. They're sitting as a destination. Users are out there and they go through a zero trust. A firewall creates a moat around a castle, so you can go in the castle over the castle. We believe in the world of cloud, there's no room for firewall. So I have customers who are running hundreds and hundreds of applications in public cloud, and they don't have firewalls. They go through ZPA because ZPA says, I don't need a firewall that says, can you come in or not? It's a poise that says, don't call me, I will call you if I need to talk to you. It's a very cool new approach. And that's what ZPA, zero trust talks about. Now people say, why don't go and replace firewalls in a data center. So we're doing some of that, but I tell you why I'm not focused on it. I don't need to take a fight in a market, in an area that's dying, okay? I want to go where the puck is headed. Why should I pick a fight where the puck is today? Today, applications are moving out. I was talking to the CIO just this week, and she said, in 2 weeks, my last data center will be retired, okay? Our data center has a lot of stuff in it, lots of routers, switches, firewalls, proxies, VPN, you name it. Some of these when customers don't even know what all they have and what will break if they try to replace it. So most of the CIOs tell me that I don't need to mess with a data center. It is going to wither away over time. Let's focus on a public level where the traffic is headed. But this is all you should think about it. Traditionally, the traffic from hundreds and hundreds of branches, it goes to the data center because data center has been the center of the universe, right? It's the center of gravity. And then either the user went to use SAP in the data center or through the data center, through some Blue Coat or [indiscernible] proxies, it went out to the Internet. But all that traffic was coming there. You needed to keep on buying bigger routers, bigger switches, bigger firewalls, bigger proxies and everything. Now in the new world, the traffic simply goes from every branch office, every home user, it goes directly to the Internet. If you start doing that, the amount of traffic that needs to go to the data center or application sitting in the data center, literally, comes down from 100% down to about 30% or 40%. And as your applications move to a public cloud, user need to go direct to those Azure and AWS based application, not through the data center. Once they do that, the traffic going through the data center comes down -- will come down to 20%, 15%, 10% as a matter of time. And do you think they'll need to buy any more routers and firewalls and stuff in the data center, they won't. As long as the hub and scope is there, they'll keep on buying it for a while, just like they kept on buying proxies for a while. But it's a matter of time when the traffic will fall off. Now will there be firewalls in 10 years in the data center somewhere, there will be some. Just like the mainframes I sold during my days at IBM. They're still sitting in home basement. They're running it. But is the world really is about mainframes? No. In the same way, I think firewalls will hang around linger on in data centers for a while but the real business is happening in public cloud, and that's where ZPA is playing a very important role to protect them the new way rather than trying to do the old school legacy network segmentation.

Mandeep Singh

analyst
#23

Got it. And last couple of questions. So do you think there is a need for standardization when it comes to a Zero Trust architecture? And the second part of the question is, what gives you the conviction that proxy based cloud security will not get commoditized?

Jagtar Chaudhry

executive
#24

So good point. So they're 2 very separate questions. Need for standardization in zero trust. Zero trust is actually based on some very core principles, don't connect the user to the network, connect them to applications alike. So yes, there'll be vendors trying to implement this core concept, which doesn't people -- put people on the network. I think standardization is needed in many of the areas, for example, the biggest need of standardization was integration with identity. Thank god our SAML standard, SAML standard evolved 10, 12 years ago, and all identity vendors use that standard. So integration happens very well. So I think that are lots of APIs available for standardization. There's no lack of it. It needs to be -- integration work needs to be done and Zscaler has invested in doing so. Your second question was my conviction to say proxy doesn't get commoditized. Technology is mature. We started as a basic proxy, doing 3, 4 things. It started with web filtering, antivirus, then we ended data protection, then we added sandboxing, then we added quality of service, then we had an outbound firewall. Now we are adding browser isolation. The platform is growing wider and deeper. So it's not a static market that kind of someone comes from behind. And two, being able to do all these things in an integrated fashion gets very hard, unless you build a meaningful platform on which you can extend these products, it will be hard to do. So the barrier to entry to have a proxy, which is the best architecture for inspection or content and SSL inspection. To do it at speed across the globe for millions of users, distributor around with policy that instantaneously shows up, but appeases the logs that come back. The IP is so big. A barrier to entry are massive. So I think it will be very hard for someone to come from behind. Having said that, we believe in what Andy Grove said, "Only paranoid will survive." So we keep on innovating. We are investing heavily in R&D. And look at how fast our product lines have come. I look at Zscaler's offerings like a pharma company looks at the drug pipeline, right? I am doing a lot of growth business, my growth engines are Zscaler Internet Access and ZPA. I just introduced ZDX, Zscaler Digital Experience that further expands my TAM and differentiates my solution. And every customer of Zscaler wants -- ZIA customer wants, ZPA. ZPA customer wants ZIA and all those customer wants ZDX. And then the new nascent market area, which is my workload protection, we actually have investing heavily in that space. We think that's a nascent market and the nascent technologies out there. There's no dominant player. Whatever is being done is being done the old way, trying to do virtual firewalls and the like. If firewalls were such a headache in the data center for network segmentation, how could they succeed in a public cloud where workloads are being spun up, up and down thousands of times a day and an approach with zero trust the way Zscaler is doing is going to succeed. So we believe because of innovations we are driving, expeditional integrated functionality we are offering because our customers are happy, they love us because they've done such a great job because a customer -- a large customer won't just depend upon a large vendor whose technology doesn't work or a young vendor who seems promising, but the customer doesn't have trust and confidence in. We have the trust and confidence of our large customers we have a growing evolving technology, we think it will give us a differentiation for long run.

Mandeep Singh

analyst
#25

Got it. And my last question is on the demand environment. So COVID has been a nice tailwind in terms of driving this wave around remote work and really, I think it's accelerated the adoption of cloud security. So do you think any -- is there any change in sales cycle or demand because of the upcoming elections?

Jagtar Chaudhry

executive
#26

Yes. So COVID has clearly changed things. It changed the mindset of people. The CIO's saying, wow, I can actually -- forget about network transformation, I can actually give up my network because Internet is my network. So it's actually helped us big time. Election, I think probably the certain bodies were more into whatever election security. If you look at a lot of large enterprises, they're mindful of it, but they view themselves less as a target for it. So is it a big accelerator? Not really. Is it raising awareness because everyone is getting educated about what can be done? Yes, it is raising awareness. But COVID has been a big accelerator.

Mandeep Singh

analyst
#27

Got it. Thank you so much Jay for taking the time to speak to us. This has been absolutely wonderful. Pleasure having you for the full hour. And with that, we will wrap up. There are slides that we'll be sending along with the playback link. And again, thank you, Jay, for your time, and we look forward to another session with you at some point later.

Jagtar Chaudhry

executive
#28

Great. Mandeep, thank you so much. I appreciate it. Goodbye.

Mandeep Singh

analyst
#29

That concludes the webinar. Thank you all.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Zscaler, Inc. transcript — plus 251,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Zscaler, Inc. earnings transcripts and 251,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.